ISC2 CISSP (Certified Information Systems Security Professional)Communication and Network SecurityMedium
A network security team is deploying an Intrusion Prevention System (IPS) in an inline mode to protect a critical web application server. Which of the following is a primary risk associated with deploying an IPS in inline mode, particularly for latency-sensitive applications?
- AInability to block malicious traffic effectively without impacting performance.
- BIncreased false positive alerts requiring manual review.
- CThe IPS becoming a single point of failure for network traffic.
- DDifficulty in scaling the IPS solution to handle increased traffic volume.
Show answer & explanationAnswer & explanation
Correct answer: C. The IPS becoming a single point of failure for network traffic.
When an IPS is deployed inline, all network traffic must pass through it. If the IPS fails or experiences issues, it can halt or disrupt all traffic to the protected segment, making it a single point of failure.
Why the other options are wrong
- A. Inline IPS is designed to block effectively; performance impact is a factor but not the *primary risk* of a single point of failure which can cause total outage.
- B. False positives are a concern for both IPS and IDS, regardless of deployment mode, but not the primary risk specific to inline deployment causing operational disruption.
- D. Scaling can be a challenge, but it's a design/capacity planning issue rather than an inherent risk of the inline deployment model itself causing immediate outage upon failure.
IPS Inline Mode
An Intrusion Prevention System deployment where all network traffic passes directly through the IPS, allowing it to actively block or prevent detected threats.
- Acts as a gatekeeper, sits 'in-line' with network traffic.
- Can actively drop malicious packets or reset connections.
- Introduces latency and can be a single point of failure.
Memory trick: Inline IPS is a 'Traffic Cop' that can 'Stop' everything.